Sr. IT Risk Management and Compliance Specialist (Wickliffe, OH, US, 44092-2298)

Remote, USA Full-time
About the position At Lubrizol, we're transforming the chemical industry and looking for exceptional talent to join us on this journey. If you are ready to join an international company with talent around the world and want to make a real impact, we want you on our team. As a Sr. IT Risk Management and Compliance Specialist, you'll be a key resource in the development and continuous improvement of all aspects of the company's global Information Security program, including Third Party Risk Management. You'll collaborate with a diverse group of passionate individuals to deliver sustainable solutions to advance mobility, improve wellbeing and enhance modern life. You will help lead the development and execution of enterprise-wide risk strategies and processes, mentor junior team members, and serve as a key advisor to leadership on compliance trends. This role entails the ongoing utilization and enhancement of our risk management, compliance, and governance programs. You will be a partner with technical teams to advise on applicable control requirements and potential solutions, ensuring that third-party relationships are managed effectively and securely. In addition to Third Party Risk Management, you will also be involved in internal auditing activities. You will participate in measuring and reporting compliance with IT policies and standards to leadership, conducting audits and mentoring junior team members to conduct audits to assess the effectiveness and efficiency of risk management processes. This includes evaluating internal controls, identifying areas for improvement, and recommending and implementing enhancements to the program. Furthermore, you will be responsible for responding to external requests related to IT risk management and compliance. They will collaborate with relevant stakeholders to address inquiries, provide necessary documentation, and ensure compliance with external regulations and standards. The Senior IT Risk Management and Compliance Specialist plays a critical role in ensuring the global impact and importance of Lubrizol's Information Security program by managing risks, conducting internal audits, and responding to external requests Responsibilities • Execute the IT Risk Management processes to identify, assess, evaluate, and treat risks, ensuring the global impact and importance of Lubrizol's Information Security program. • Recommend and implement Risk Management, Compliance, and Governance Programs process improvements to enhance the effectiveness and efficiency. • Facilitate and conduct technology and operational risk and compliance assessments to identify potential risks and ensure compliance with internal policies and external regulations. • Respond to and support risk assessments or audits from external and internal customers, providing necessary documentation and addressing inquiries to ensure compliance and risk mitigation. • Partner with technical teams, advising on applicable control requirements and proposing potential solutions to address identified risks, fostering a secure and compliant environment. • Conduct compliance assessments of controls for in-scope systems, including remediation assessments and audit-readiness assessments, to ensure adherence to IT policies and standards. • Identify control deficiencies and maintain records of deficiency details, including management response documentation and evidence of exposure checks, to track and address areas for improvement. • Collaborate on the 3rd Party Risk Management program, managing and mitigating risks associated with third-party relationships. • Maintain and improve the Information Security Policy Set, ensuring that policies are up to date, aligned with industry best practices, and effectively communicated to employees. • Provide insight and recommendations to leadership as part of a global information security team, contributing to strategic decision-making and continuous improvement efforts. • Perform other information security activities as needed to support the overall objectives of the Information Security program at Lubrizol Requirements • Bachelor's degree in Information Technology (IT), Information Security or a related field, providing a strong foundation in IT and Information Security principles and practices. • Minimum of 3 years of relevant industry and professional experience in areas such as risk management, audit, third-party risk, operational risk, information security, or related fields. • Practical knowledge of third-party risk management, including the ability to assess and manage risks associated with external vendors and partners. Experience with IT risk assessments and operational processes is also valuable, as well as familiarity with techniques for implementing regulatory requirements. • Solid understanding of security domains, including identity and access management, authentication, encryption, application security, network security, vulnerability and patch management, information security metrics, policies, standards, and procedures. • Experience with ISO and NIST security standards, which are widely recognized frameworks for information security management. • Expertise in tracking and analyzing emerging cybersecurity threats, risks, and trends, and contextualizing them within the specific business processes, assets, and personnel of the company. • Proficiency in Microsoft Windows-based operating systems and collaboration tools, enabling effective communication and collaboration within the organization. • Demonstrated understanding of risk management processes, including the ability to identify, assess, evaluate, and treat risks in a systematic and structured manner. • Knowledge of basic IT security principles, networking concepts, active directory, and SAP ECC/S4 concepts. • Familiarity with risk management frameworks, such as ISO 31000 or COSO ERM, providing a structured approach to managing risks and ensuring compliance with industry standards. • Ability to resolve issues via undocumented methods through research and investigation, demonstrating resourcefulness and problem-solving skills in addressing complex challenges. • Experience in documenting issues and solutions to assist end users and co-workers in understanding and resolving similar problems, promoting knowledge sharing and collaboration within the organization. • Strong analytical and problem-solving skills, enabling the ability to analyze complex information, identify patterns, and make informed decisions to mitigate risks. • Knowledge of regulatory compliance requirements, such as GDPR, HIPAA, or SOX, depending on the industry and region of operation. • Familiarity with data privacy and protection principles, including data classification, data retention, and data breach response. • Experience with conducting risk assessments and developing risk mitigation strategies. • Proficiency in using risk management tools and software, such as GRC (Governance, Risk, and Compliance) platforms or risk assessment software. • Understanding of incident response and business continuity planning, including the ability to develop and test incident response plans. • Knowledge of cloud computing security principles and best practices, including familiarity with cloud service provider security frameworks (e.g., AWS, Azure, Google Cloud). • Strong project management skills, including the ability to manage multiple projects simultaneously, prioritize tasks, and meet deadlines. • Excellent communication and presentation skills, with the ability to effectively communicate complex technical concepts to both technical and non-technical stakeholders. • Continuous learning mindset, staying updated with the latest trends, technologies, and regulatory changes in the field of IT risk management and compliance Nice-to-haves • Preferred certifications include CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor). • Operational knowledge of a risk management system, such as AuditBoard, RSA Archer or ServiceNow IRM, is preferred. • Experience with CIS (Center for Internet Security) benchmarks and controls is preferred. Familiarity with these controls demonstrates an understanding of industry-recognized security practices and their application in risk management and compliance efforts. Benefits • Competitive salary with performance-based bonus plans • 401K Match plus Age Weighted Defined Contribution • Competitive medical, dental & vision offerings • Health Savings Account • Paid Holidays, Vacation, Parental Leave • Flexible work environment Apply tot his job
Apply Now

Similar Jobs

Risk & Compliance - Associate Manager

Remote, USA Full-time

Business Risk Analyst Senior - onsite, Columbus or Remote GA AL TN SC FL

Remote, USA Full-time

Due Diligence Manager-Third Party Risk

Remote, USA Full-time

[Remote] Compliance Officer II – Risk Assessment (Remote)

Remote, USA Full-time

Online Safety and Risk Management Consultant

Remote, USA Full-time

Cybersecurity Risk Assessment Engagement Manager (Project Manager) - Contingent

Remote, USA Full-time

GRC Risk Analyst

Remote, USA Full-time

Production Support Risk Assessment Manager

Remote, USA Full-time

[Remote] Medicare Sales Field Agent - San Diego, CA

Remote, USA Full-time

National Property Claims Adjuster - Multiple Levels (Level 1-2)

Remote, USA Full-time

Hybrid Auto Insurance Claims Adjuster (Office/Remote), Spanish

Remote, USA Full-time

Part Time Remote Customer Service Representative - Insurance Industry at blithequark

Remote, USA Full-time

Wait Staff / Server – Amazon Store

Remote, USA Full-time

Workday Engagement Manager (Higher Ed)

Remote, USA Full-time

**Experienced Customer Service Representative – Evening & Weekend Shifts at blithequark**

Remote, USA Full-time

**Experienced Remote Data Entry Clerk / Typist – Flexible Work from Home Opportunity at blithequark**

Remote, USA Full-time

Team Lead – Channel

Remote, USA Full-time

**Experienced Live Chat Support Agent – Entry-Level Opportunity for Remote Customer Service Professionals**

Remote, USA Full-time

Research Associate, Analytical Chemistry

Remote, USA Full-time

Experienced Entry Level Financial Planner for Diverse Client Base in NV, AZ, NM - Unlock a Rewarding Career with Equitable Advisors

Remote, USA Full-time
Back to Home